@omegaengine/mcp
v0.2.0
Published
Model Context Protocol server for OmegaEngine — govern, red-team, and cryptographically verify every AI agent action.
Maintainers
Readme
@omegaengine/mcp
The exact-action control layer for AI agents — as an MCP server.
Drop OmegaEngine into any Model Context Protocol client (Claude Desktop, Cursor, Windsurf, and the rest) and your agent can govern, escalate, red-team, and verify consequential actions before execution.
Execution rule: invoke the side-effecting tool only when
decisionisapprovedand anexecution_capabilityis present. The capability is bound to the exacttool_name+tool_args.
Tools
| Tool | What it does |
|---|---|
| check_action | Govern exact tool_name + tool_args before execution; approved live calls return a one-use capability. |
| claim_approval | After human approval, re-check the authorization and claim its exact-action capability; pending or denied stays blocked. |
| scan_agent | Red-team an agent's prompt + tools against the attack corpus (prompt injection, tool-call injection, data exfiltration, excessive agency). Returns the exploits found. |
| verify_proof | Cryptographically verify a signed OmegaEngine decision envelope. |
Install
npx -y @omegaengine/mcp # runs the server (stdio)Claude Desktop / Cursor / Windsurf
Add to your MCP config (claude_desktop_config.json, Cursor mcp.json, etc.):
{
"mcpServers": {
"omega-engine": {
"command": "npx",
"args": ["-y", "@omegaengine/mcp"],
"env": {
"OMEGA_API_KEY": "your-omegaengine-api-key",
"OMEGA_BASE_URL": "https://omegaengine.ai"
}
}
}
}OMEGA_API_KEY— your OmegaEngine API key (get one free). Required forcheck_action.scan_agent(sample mode) andverify_proofwork without it.OMEGA_BASE_URL— defaults tohttps://omegaengine.ai. Point it at your self-hosted instance (e.g.http://localhost:3000) to keep everything on-prem.
Remote MCP (no install)
Clients that support remote MCP servers can skip this package entirely: the hosted API exposes the
same four tools over MCP Streamable HTTP at POST https://omegaengine.ai/api/mcp (stateless
JSON-RPC; x-api-key header auth on every request — MCP OAuth not yet available).
{
"mcpServers": {
"omega-engine": {
"url": "https://omegaengine.ai/api/mcp",
"headers": { "x-api-key": "your-omegaengine-api-key" }
}
}
}Example
Once connected, your agent can call:
check_action(
agent_id="support-agent",
action="refund order 4421",
tool_name="stripe.refunds.create",
tool_args={"payment_intent":"pi_4421","amount":4200},
amount=42,
vendor="stripe",
idempotency_key="refund-order-4421"
)
→ { "decision": "escalated", "authorization_id": "authz_7x8k…", "execution_capability": null }
# The action remains blocked. After a human approves it:
claim_approval(
authorization_id="authz_7x8k…",
agent_id="support-agent",
idempotency_key="claim-authz-7x8k"
)
→ { "decision": "approved", "action_hash": "…", "execution_capability": "eyJ2Ijox…" }
scan_agent(system_prompt="You are a support agent…", tools=[…], openai_api_key="sk-…")
→ { "summary": { "exploited": 3, "worst": "critical" }, "results": [ … send_email→[email protected] … ] }
verify_proof(decision={…}, signature="omega-3190df…")
→ { "valid": true, "tampered": false }Build from source
npm install && npm run build && node dist/index.jsSecurity
- The server is a thin client — the engine, audit trail, and signing live in OmegaEngine. No decision logic runs locally.
check_actionandclaim_approvalalways send an idempotency key; callers can supply a stable key so transport retries replay the same result instead of authorizing twice.denied,escalated, missing-capability, timeout, network, and malformed responses are all non-executable states.scan_agent'sopenai_api_keyis used in-request only, never stored or logged.- Diagnostics are written to stderr; stdout is reserved for the MCP transport.
Apache-2.0 · omegaengine.ai
